Skip to content

NightLedger

NightLedger is a Windows backdoor attributed to the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm.

Profile source: Mallory opens in a new tab

NightLedger

Family profile

NightLedger is a Windows backdoor attributed to the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm. It is used in operations targeting organizations in the Middle East, Africa, and South Asia, including aerospace, aviation, defense, telecommunications, government, financial-sector, and small-business entities. NightLedger masquerades as a legitimate Windows component and executes through DLL search-order hijacking. It communicates with command-and-control infrastructure over HTTPS and supports host and user reconnaissance, directory and logical-drive enumeration, process listing and management, process execution, DLL loading, file download, upload, copying, and deletion, screenshot capture, and collection of Windows diagnostic logs. Its command protocol and development characteristics overlap with the actor's previously observed TWOSTROKE backdoor. NightLedger has been used alongside the BridgeHead and ArcBridge tunneling utilities to support covert, long-term access to compromised environments.

Capabilities

  • Dll Sideloading
  • Exfiltration
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

5 named in public reporting
Mirage Kitten

Kaspersky documented the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools in July 2026.

Nimbus Manticore

The article lists "a Windows backdoor called NightLedger" among Nimbus Manticore's recently expanded malware arsenal.

galaxygato

Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.

CURIUM

Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.

Imperial Kitten

Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.

MITRE ATT&CK

NightLedger in ATT&CK

18 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.